TW202042063A - Method and computer storage node of shared storage system for abnormal behavior detection/analysis - Google Patents

Method and computer storage node of shared storage system for abnormal behavior detection/analysis Download PDF

Info

Publication number
TW202042063A
TW202042063A TW109108697A TW109108697A TW202042063A TW 202042063 A TW202042063 A TW 202042063A TW 109108697 A TW109108697 A TW 109108697A TW 109108697 A TW109108697 A TW 109108697A TW 202042063 A TW202042063 A TW 202042063A
Authority
TW
Taiwan
Prior art keywords
detection signal
pattern
reference signal
display panel
signal
Prior art date
Application number
TW109108697A
Other languages
Chinese (zh)
Other versions
TWI747199B (en
Inventor
陳建穎
楊伯安
Original Assignee
香港商希瑞科技股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 香港商希瑞科技股份有限公司 filed Critical 香港商希瑞科技股份有限公司
Publication of TW202042063A publication Critical patent/TW202042063A/en
Application granted granted Critical
Publication of TWI747199B publication Critical patent/TWI747199B/en

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F3/00Input arrangements for transferring data to be processed into a form capable of being handled by the computer; Output arrangements for transferring data from processing unit to output unit, e.g. interface arrangements
    • G06F3/06Digital input from, or digital output to, record carriers, e.g. RAID, emulated record carriers or networked record carriers
    • G06F3/0601Interfaces specially adapted for storage systems
    • G06F3/0602Interfaces specially adapted for storage systems specifically adapted to achieve a particular effect
    • G06F3/0604Improving or facilitating administration, e.g. storage management
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/30Monitoring
    • G06F11/3003Monitoring arrangements specially adapted to the computing system or computing system component being monitored
    • G06F11/3034Monitoring arrangements specially adapted to the computing system or computing system component being monitored where the computing system component is a storage system, e.g. DASD based or network based
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/07Responding to the occurrence of a fault, e.g. fault tolerance
    • G06F11/0703Error or fault processing not based on redundancy, i.e. by taking additional measures to deal with the error or fault not making use of redundancy in operation, in hardware, or in data representation
    • G06F11/0751Error or fault detection not based on redundancy
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/30Monitoring
    • G06F11/32Monitoring with visual or acoustical indication of the functioning of the machine
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/30Monitoring
    • G06F11/32Monitoring with visual or acoustical indication of the functioning of the machine
    • G06F11/321Display for diagnostics, e.g. diagnostic result display, self-test user interface
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/30Monitoring
    • G06F11/34Recording or statistical evaluation of computer activity, e.g. of down time, of input/output operation ; Recording or statistical evaluation of user activity, e.g. usability assessment
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F3/00Input arrangements for transferring data to be processed into a form capable of being handled by the computer; Output arrangements for transferring data from processing unit to output unit, e.g. interface arrangements
    • G06F3/06Digital input from, or digital output to, record carriers, e.g. RAID, emulated record carriers or networked record carriers
    • G06F3/0601Interfaces specially adapted for storage systems
    • G06F3/0628Interfaces specially adapted for storage systems making use of a particular technique
    • G06F3/0653Monitoring storage devices or systems
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F3/00Input arrangements for transferring data to be processed into a form capable of being handled by the computer; Output arrangements for transferring data from processing unit to output unit, e.g. interface arrangements
    • G06F3/06Digital input from, or digital output to, record carriers, e.g. RAID, emulated record carriers or networked record carriers
    • G06F3/0601Interfaces specially adapted for storage systems
    • G06F3/0668Interfaces specially adapted for storage systems adopting a particular infrastructure
    • G06F3/067Distributed or networked storage systems, e.g. storage area networks [SAN], network attached storage [NAS]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/10Protocols in which an application is distributed across nodes in the network
    • H04L67/1097Protocols in which an application is distributed across nodes in the network for distributed storage of data in networks, e.g. transport arrangements for network file system [NFS], storage area networks [SAN] or network attached storage [NAS]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/50Network services
    • H04L67/535Tracking the activity of the user
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/30Monitoring
    • G06F11/3055Monitoring arrangements for monitoring the status of the computing system or of the computing system component, e.g. monitoring if the computing system is on, off, available, not available
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/30Monitoring
    • G06F11/34Recording or statistical evaluation of computer activity, e.g. of down time, of input/output operation ; Recording or statistical evaluation of user activity, e.g. usability assessment
    • G06F11/3409Recording or statistical evaluation of computer activity, e.g. of down time, of input/output operation ; Recording or statistical evaluation of user activity, e.g. usability assessment for performance assessment
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/30Monitoring
    • G06F11/34Recording or statistical evaluation of computer activity, e.g. of down time, of input/output operation ; Recording or statistical evaluation of user activity, e.g. usability assessment
    • G06F11/3409Recording or statistical evaluation of computer activity, e.g. of down time, of input/output operation ; Recording or statistical evaluation of user activity, e.g. usability assessment for performance assessment
    • G06F11/3419Recording or statistical evaluation of computer activity, e.g. of down time, of input/output operation ; Recording or statistical evaluation of user activity, e.g. usability assessment for performance assessment by assessing time
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/12Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L69/00Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
    • H04L69/40Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass for recovering from a failure of a protocol instance or entity, e.g. service redundancy protocols, protocol state redundancy or protocol service redirection

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • General Engineering & Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Quality & Reliability (AREA)
  • Computing Systems (AREA)
  • Human Computer Interaction (AREA)
  • Computer Hardware Design (AREA)
  • Mathematical Physics (AREA)
  • Signal Processing (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Debugging And Monitoring (AREA)

Abstract

A method utilized in a computer storage node includes: providing user interface device to be operated by an operator; providing sensor module to sense operation parameter of computer storage node to generate first detection signal and second detection signal following first detection signal; receiving first detection signal to control display panel of user interface device to display data pattern of first detection signal on display panel according to a time scale; using first portion of first detection signal corresponding to a partial pattern of the data pattern to generate reference signal when the operator uses user interface device to mark a region on display panel to select the partial pattern; receiving second detection signal sent from sensor module after the reference signal is generated; and comparing characteristics of reference signal with characteristics of second detection signal to perform behavior analysis operation.

Description

用以異常行為偵測或分析的共用儲存系統的方法與計算機儲存節點Method and computer storage node for shared storage system for abnormal behavior detection or analysis

本發明關於一分散式共用儲存系統,特別有關於在該系統中的一計算機儲存節點以及使用在該計算機儲存節點中的方法。The present invention relates to a distributed shared storage system, and particularly relates to a computer storage node in the system and a method used in the computer storage node.

一般來說,對於信息技術的操作者或使用者而言,一共用儲存系統的操作與維護的設計是一大挑戰,該挑戰包括了如何預測該儲存系統的效能與容量是否滿足未來的需求及/或當偵測到一異常存取行為時如何及時產生一個警示回報給該操作者以令該操作者能夠及時地回應該異常行為。Generally speaking, for information technology operators or users, the design of the operation and maintenance of a shared storage system is a big challenge. The challenge includes how to predict whether the performance and capacity of the storage system will meet future needs and /Or how to generate a warning report to the operator in time when an abnormal access behavior is detected so that the operator can respond to the abnormal behavior in time.

因此本發明的目的之一在於提供一種使用於一分散式共用儲存系統中多個計算機儲存節點的其中一個的方法以及計算機儲存節點,以解決傳統技術的問題。Therefore, one of the objectives of the present invention is to provide a method and computer storage node used in one of a plurality of computer storage nodes in a distributed shared storage system to solve the problems of the traditional technology.

根據本發明實施例,其揭露了一種使用於一分散式共用儲存系統中多個計算機儲存節點的其中之一的方法。該方法包含有:提供被一操作者所操作的一使用者介面裝置;提供一感測器模組以感測該計算機儲存節點的至少一操作參數以產生一第一偵測訊號與跟隨該第一偵測訊號的一第二偵測訊號;以及,提供並使用一處理器來執行:接收該第一偵測訊號以控制該使用者介面裝置的一顯示面板以於該顯示面板上根據一時間尺度來顯示該第一偵測訊號的一資料型樣;當該操作者使用該使用者介面裝置來標示該顯示面板上的一區域以選取該資料型樣的一部分的型樣時,使用相應於該資料型樣的該部分的型樣之該第一偵測訊號的一第一部分來產生一參考訊號;在產生該參考訊號之後,接收從該感測器模組所傳送的該第二偵測訊號;以及比較該參考訊號的特性與該第二偵測訊號的特性以執行一行為分析操作。According to an embodiment of the present invention, it discloses a method used in one of multiple computer storage nodes in a distributed shared storage system. The method includes: providing a user interface device operated by an operator; providing a sensor module to sense at least one operating parameter of the computer storage node to generate a first detection signal and follow the first detection signal A second detection signal of a detection signal; and, providing and using a processor to execute: receiving the first detection signal to control a display panel of the user interface device to be based on a time on the display panel Scale to display a data pattern of the first detection signal; when the operator uses the user interface device to mark an area on the display panel to select a part of the data pattern, use the pattern corresponding to A first part of the first detection signal of the pattern of the part of the data pattern to generate a reference signal; after generating the reference signal, receive the second detection transmitted from the sensor module Signal; and comparing the characteristics of the reference signal with the characteristics of the second detection signal to perform a behavior analysis operation.

根據本發明實施例,其揭露了一種於一分散式共用儲存系統中多個計算機儲存節點中的計算機儲存節點。該計算機儲存節點包含有一使用者介面裝置、一感測器模組以及一處理器。該使用者介面裝置包含有一顯示面板與至少一計算機輸入裝置,該顯示面板用來顯示資訊給一使用者,該至少一計算機輸入裝置由一操作者所操作。該感測器模組用來感測該計算機儲存節點的至少一操作參數以產生一第一偵測訊號與跟隨該第一偵測訊號的一第二偵測訊號。該處理器耦接至該使用者介面裝置與該感測器模組,並用來:接收該第一偵測訊號以控制該使用者介面裝置的一顯示面板以於該顯示面板上根據一時間尺度來顯示該第一偵測訊號的一資料型樣;當該操作者使用該使用者介面裝置來標示該顯示面板上的一區域以選取該資料型樣的一部分的型樣時,使用相應於該資料型樣的該部分的型樣之該第一偵測訊號的一第一部分來產生一參考訊號;在產生該參考訊號之後,接收從該感測器模組所傳送的該第二偵測訊號;以及比較該參考訊號的特性與該第二偵測訊號的特性以執行一行為分析操作。According to an embodiment of the present invention, a computer storage node among multiple computer storage nodes in a distributed shared storage system is disclosed. The computer storage node includes a user interface device, a sensor module and a processor. The user interface device includes a display panel and at least one computer input device, the display panel is used to display information to a user, and the at least one computer input device is operated by an operator. The sensor module is used for sensing at least one operating parameter of the computer storage node to generate a first detection signal and a second detection signal following the first detection signal. The processor is coupled to the user interface device and the sensor module, and is used to: receive the first detection signal to control a display panel of the user interface device according to a time scale on the display panel To display a data pattern of the first detection signal; when the operator uses the user interface device to mark an area on the display panel to select a part of the data pattern, use the pattern corresponding to the A first part of the first detection signal of the pattern of the part of the data pattern to generate a reference signal; after generating the reference signal, receive the second detection signal transmitted from the sensor module And comparing the characteristics of the reference signal with the characteristics of the second detection signal to perform a behavior analysis operation.

本發明提供新穎的技術解決方案以解決傳統的問題,基於本發明所提供的解決方案,操作者可有效地且輕易地經由一使用者介面裝置來定義一偵測訊號的一部分為正常型樣及/或異常型樣,以及本發明所提供的儲存系統可以將所定義的正常型樣及/或異常型樣儲存為一或多個特定參考型樣並接著比較該一或多個參考型樣的特性與一接收進來的偵測訊號的特性來執行一行為分析操作,以便決定是否發生了一異常操作行為。The present invention provides novel technical solutions to solve traditional problems. Based on the solutions provided by the present invention, the operator can effectively and easily define a part of a detection signal as a normal pattern through a user interface device. /Or abnormal patterns, and the storage system provided by the present invention can store the defined normal patterns and/or abnormal patterns as one or more specific reference patterns and then compare the one or more reference patterns Characteristics and a characteristic of receiving the incoming detection signal to perform a behavior analysis operation to determine whether an abnormal operation behavior occurs.

第1圖是本發明一實施例之去中心化儲存系統100的方塊示意圖,該系統100係通過由一分散式網路所實現並包含有多個計算機儲存節點105,每一計算機儲存節點105係經由一內部共用網路而連接到其他的多個計算機儲存節點105,該多個計算機儲存節點105係被聚集在一起(clustered together),一客戶使用者可以經由一外部網路而連接至某一個計算機儲存節點,而如果一個計算機儲存節點的運作失敗,則該客戶使用者的要求會被重新導向至另一個工作中的計算機儲存節點。此外,該系統100可以支援多種特定通訊協定,例如iSCSI、NFS、Samba等等,此外,該系統100可以支援虛擬儲存的功能;以上的發明變型均並非是本發明的限制。Figure 1 is a block diagram of a decentralized storage system 100 according to an embodiment of the present invention. The system 100 is implemented by a distributed network and includes a plurality of computer storage nodes 105, and each computer storage node 105 is It is connected to other multiple computer storage nodes 105 via an internal shared network. The multiple computer storage nodes 105 are clustered together. A customer user can connect to a certain one via an external network Computer storage node, and if the operation of a computer storage node fails, the client user’s request will be redirected to another working computer storage node. In addition, the system 100 can support a variety of specific communication protocols, such as iSCSI, NFS, Samba, etc. In addition, the system 100 can support the function of virtual storage; the above invention variants are not a limitation of the present invention.

第2圖是本發明一實施例之一計算機儲存節點105的方塊示意圖,該計算機儲存節點105包含有一使用者介面裝置110、一多核心的處理器115(包括有一或多個中央處理器CPU)、一感測器模組120、一網路介面控制器(network interface controller,NIC)125(例如是一網路介面卡)、一靜態隨機存取記憶體(SRAM)130用來作為該處理器的快取、一主機介面控制器(SATA)135、一動態隨機存取記憶體(DRAM)緩衝器140、一快閃記憶體控制器145、一或多個硬碟驅動機(hard-disk drives,HDD)150(例如有兩個硬碟驅動機)、以及一或多個固態硬碟(solid-state drives,SSD)155(例如使用NAND型的快閃記憶體晶片所實現的四個固態硬碟);硬碟驅動機的個數以及固態硬碟的個數均並非是本案的限制。Figure 2 is a block diagram of a computer storage node 105 according to an embodiment of the present invention. The computer storage node 105 includes a user interface device 110 and a multi-core processor 115 (including one or more central processing units (CPU)) A sensor module 120, a network interface controller (NIC) 125 (for example, a network interface card), and a static random access memory (SRAM) 130 are used as the processor Cache, a host interface controller (SATA) 135, a dynamic random access memory (DRAM) buffer 140, a flash memory controller 145, one or more hard-disk drives , HDD) 150 (for example, two hard disk drives), and one or more solid-state drives (solid-state drives, SSD) 155 (for example, four solid-state hard disks realized by using NAND-type flash memory chips) Disk); the number of hard disk drives and the number of solid-state hard disks are not the limitation of this case.

使用者介面裝置110包含有用以顯示內容/資訊給一操作者的一顯示面板1101以及至少一計算機輸入裝置1102(例如一電腦鍵盤及一電腦滑鼠),該處理器115係經由該控制匯流排而耦接至該顯示面板1101與多個計算機輸入裝置1102並可發送資訊/訊號至該顯示面板1101與多個計算機輸入裝置1102或是接收從該顯示面板1101與多個計算機輸入裝置1102來的資訊/訊號,該使用者介面裝置110係用來顯示資訊給該操作者/使用者以及接收該操作者的輸入控制命令,其中該多個計算機輸入裝置1102可被該操作者/使用者所操控。The user interface device 110 includes a display panel 1101 useful for displaying content/information to an operator and at least one computer input device 1102 (such as a computer keyboard and a computer mouse), and the processor 115 passes through the control bus It is coupled to the display panel 1101 and multiple computer input devices 1102 and can send information/signals to the display panel 1101 and multiple computer input devices 1102 or receive data from the display panel 1101 and multiple computer input devices 1102. Information/signal, the user interface device 110 is used to display information to the operator/user and receive input control commands from the operator, wherein the plurality of computer input devices 1102 can be controlled by the operator/user .

處理器115係經由控制匯流排而耦接至該主機介面控制器135、該SRAM130、該DRAM緩衝器140、該感測器模組120、該網路介面控制器125、該使用者介面裝置110以及該快閃記憶體控制器145,並被安排用來發送命令以控制上述所提到的裝置以及執行複雜的計算,其中複雜的計算所需要的資料可以被快取暫存於SRAM130。The processor 115 is coupled to the host interface controller 135, the SRAM 130, the DRAM buffer 140, the sensor module 120, the network interface controller 125, and the user interface device 110 through a control bus And the flash memory controller 145 is arranged to send commands to control the aforementioned devices and perform complex calculations. The data required for the complex calculations can be cached and temporarily stored in the SRAM 130.

網路介面控制器125係用來提供一外部網路IP,使得一客戶使用者可以經由網路介面控制器125而連接至該計算機儲存節點105,以存取儲存於該硬碟驅動機150或該固態硬碟155的資料。The network interface controller 125 is used to provide an external network IP so that a customer user can connect to the computer storage node 105 via the network interface controller 125 to access the storage in the hard disk drive 150 or Information on the solid state drive 155.

主機介面控制器135係經由另一匯流排而耦接至該些硬碟驅動機150並用來接收從該處理器115所發送的命令以存取儲存於該些硬碟驅動機150中的資料,舉例來說,如果一客戶使用者要求一資料或是另一計算機儲存節點要求一資料切片(data clip),則該處理器115會發送一相應的控制命令至該主機介面控制器135,接著該主機介面控制器135會經由該另一匯流排來讀取從該硬碟驅動機150來的該資料或該資料切片,以便經由該資料匯流排來寫入該資料或該資料切片至該DRAM緩衝器140,如此,該客戶使用者或該另一計算機儲存節點可以從該DRAM緩衝器140擷取得到該資料或該資料切片。The host interface controller 135 is coupled to the hard disk drives 150 via another bus and is used to receive commands sent from the processor 115 to access the data stored in the hard disk drives 150, For example, if a client user requests a data or another computer storage node requests a data clip, the processor 115 will send a corresponding control command to the host interface controller 135, and then the The host interface controller 135 reads the data or the data slice from the hard disk drive 150 via the other bus, so as to write the data or the data slice to the DRAM buffer via the data bus In this way, the customer user or the other computer storage node can retrieve the data or the data slice from the DRAM buffer 140.

快閃記憶體控制器145係經由另一匯流排而耦接至該些固態硬碟155並用來接收從該處理器115所發送的命令以存取儲存於該些固態硬碟155中的資料,舉例來說,如果一客戶使用者要求一資料或另一計算機儲存節點要求一資料切片,則該處理器115會發送一相應的控制命令至該快閃記憶體控制器145,接著該快閃記憶體控制器145經由該快閃記憶體匯流排從該固態硬碟155讀取得到該資料或該資料切片,以便經由該資料匯流排來寫入該資料或該資料切片至該DRAM緩衝器140,如此,該客戶使用者或該另一計算機儲存節點可從該DRAM緩衝器140擷取得到該資料或該資料切片。The flash memory controller 145 is coupled to the solid state drives 155 via another bus and is used to receive commands sent from the processor 115 to access the data stored in the solid state drives 155, For example, if a client user requests a data or another computer storage node requests a data slice, the processor 115 will send a corresponding control command to the flash memory controller 145, and then the flash memory The volume controller 145 reads the data or the data slice from the solid state drive 155 via the flash memory bus, so as to write the data or the data slice to the DRAM buffer 140 via the data bus, In this way, the client user or the other computer storage node can retrieve the data or the data slice from the DRAM buffer 140.

應注意的是,第2圖所示的實施例並非是本案的限制,在其他實施例,一計算機儲存節點105也可包含有同一種的多個儲存裝置,例如只有該些硬碟驅動機或是只有該些固態硬碟。It should be noted that the embodiment shown in Figure 2 is not a limitation of this case. In other embodiments, a computer storage node 105 may also include multiple storage devices of the same kind, for example, only the hard disk drives or It's only those SSDs.

處理器115可執行軟體程式與計算以存取儲存裝置(例如該些硬碟驅動機150及/或該些固態硬碟155)、接收從該感測器模組120所產生的多個偵測結果/訊號、控制該使用者介面裝置110以基於該些偵測結果/訊號來顯示該些資料型樣給該操作者以及經由該使用者介面裝置110來接收該操作者的輸入/指令,該些軟體程式可以預先被儲存或記錄於該些硬碟驅動機150或該些固態硬碟155中。The processor 115 can execute software programs and calculations to access storage devices (such as the hard disk drives 150 and/or the solid state drives 155), and receive multiple detections generated from the sensor module 120 Result/signal, control the user interface device 110 to display the data patterns to the operator based on the detection results/signals, and receive the operator’s input/command via the user interface device 110, the The software programs can be stored or recorded in the hard disk drives 150 or the solid state disks 155 in advance.

如上所述,該使用者介面裝置110可於其顯示面板1101上顯示相應於該偵測訊號之該資料型樣給該操作者,令該操作者可以於該顯示面板1101上看到該資料型樣,並令該操作者可相應地於該顯示面板1101所顯示的影像上,通過使用該電腦滑鼠來標示出一區域以選取一部分的型樣,以便選取該偵測訊號的一部分,令所選取的訊號部分可接著被傳送至該處理器115。As described above, the user interface device 110 can display the data pattern corresponding to the detection signal on the display panel 1101 to the operator, so that the operator can see the data pattern on the display panel 1101 In this way, the operator can select a part of the pattern by using the computer mouse to mark an area on the image displayed on the display panel 1101, so as to select a part of the detection signal, so that the The selected signal portion can then be sent to the processor 115.

感測器模組120被安排用來週期地執行對該計算機儲存節點105的偵測以反復地產生多個偵測訊號(亦即偵測結果),舉例來說,該感測器模組120用來感測該計算機儲存裝置105的至少一操作參數以產生一第一偵測訊號與一第二偵測訊號,該第二偵測訊號跟隨在該第一偵測訊號之後。The sensor module 120 is arranged to periodically perform detection on the computer storage node 105 to repeatedly generate multiple detection signals (that is, detection results). For example, the sensor module 120 It is used to sense at least one operating parameter of the computer storage device 105 to generate a first detection signal and a second detection signal. The second detection signal follows the first detection signal.

實作上,該感測器模組120可以通過使用多個純軟體程式演算法來實現,或是通過使用軟體程式與硬體電路的組合來實現,此非本發明的限制,舉例來說,該感測器模組120用來週期地偵測或感測CPU使用量(亦即CPU容量的百分比)、網路資料流量/封包流量的使用量、輸入/輸出型樣類型、CPU溫度、風扇轉速、儲存區使用量、該硬碟驅動機/固態硬碟的每秒讀寫次數(IOPS,input/output operations per second)、輸入/輸出延遲、檔案系統操作時間等等的至少其中一個,以產生一偵測結果/訊號至該處理器115,也就是說,該至少一操作參數包含有CPU使用量(亦即CPU容量的百分比)、網路資料流量/封包流量的使用量、輸入/輸出型樣類型、CPU溫度、風扇轉速、儲存區使用量、該硬碟驅動機/固態硬碟的每秒讀寫次數、輸入/輸出延遲、檔案系統操作時間等等的至少其中一個。In practice, the sensor module 120 can be implemented by using multiple pure software program algorithms, or by using a combination of software programs and hardware circuits. This is not a limitation of the present invention. For example, The sensor module 120 is used to periodically detect or sense CPU usage (that is, the percentage of CPU capacity), network data traffic/packet traffic usage, input/output pattern type, CPU temperature, fan At least one of speed, storage area usage, IOPS (input/output operations per second) of the hard disk drive/solid state drive, input/output delay, file system operation time, etc., to Generate a detection result/signal to the processor 115, that is, the at least one operating parameter includes CPU usage (that is, percentage of CPU capacity), network data traffic/packet traffic usage, input/output At least one of model type, CPU temperature, fan speed, storage area usage, the number of reads and writes per second of the hard disk drive/solid state drive, input/output delay, file system operation time, etc.

感測器模組120的軟體部分舉例來說可由該處理器115所啟動並執行以每N秒(多個具有N秒的時間間隔)來感測該CPU使用量,以產生該處理器115的多個百分比數值,其中N的值可以等於5或10(但不限定),而一偵測訊號包含有該處理器115每N秒的多個百分比數值。For example, the software part of the sensor module 120 can be activated and executed by the processor 115 to sense the CPU usage every N seconds (a plurality of time intervals of N seconds) to generate the processor 115 Multiple percentage values, where the value of N can be equal to 5 or 10 (but not limited), and a detection signal includes multiple percentage values of the processor 115 every N seconds.

相似地,感測器模組120的軟體部分可由該處理器115所啟動並執行,以於多個不同的時間間隔中(具有相同的秒數)來感測該網路介面控制器125,以產生該網路介面控制器125的多個累計/平均的資料流量值,而一偵測訊號此時包括有該多個累計/平均的資料流量值。Similarly, the software part of the sensor module 120 can be activated and executed by the processor 115 to sense the network interface controller 125 in a plurality of different time intervals (with the same number of seconds) to A plurality of accumulated/average data flow values of the network interface controller 125 are generated, and a detection signal now includes the plurality of accumulated/average data flow values.

相似地,該感測器模組120可被用來週期地感測該網路介面控制器125以得到該輸入/輸出型樣類型,而一偵測訊號包括有不同時間間隔的多個輸出型樣類型,舉例來說,輸出型樣類型可以是隨機輸入/輸出、依序輸入/輸出或不同的類型。感測儲存區使用量、硬碟驅動機/固態硬碟的每秒讀寫次數、延遲及檔案系統操作時間等的操作均可通過使用該處理器115週期地啟動感測器模組120的軟體部分來達成。再者,對於感測CPU溫度來說,該感測器模組120被設置包括有實體的溫度感測器電路,該實體的溫度感測器電路係用來感測該處理器115內所包括的一或多個CPU的溫度,以便產生多個所偵測到的溫度值,而該處理器115可以啟動並執行感測器模組120的軟體部分來收集多個所偵測到的溫度值以形成一偵測訊號。Similarly, the sensor module 120 can be used to periodically sense the network interface controller 125 to obtain the input/output pattern type, and a detection signal includes multiple output patterns with different time intervals. The pattern type, for example, the output pattern type can be random input/output, sequential input/output, or different types. The operation of sensing storage area usage, hard disk drive/solid state drive reads and writes per second, latency, and file system operation time can all be performed by using the processor 115 to periodically activate the software of the sensor module 120 Part of it. Furthermore, for sensing CPU temperature, the sensor module 120 is configured to include a physical temperature sensor circuit, and the physical temperature sensor circuit is used to sense the temperature of the processor 115. The temperature of one or more CPUs in order to generate multiple detected temperature values, and the processor 115 can activate and execute the software part of the sensor module 120 to collect multiple detected temperature values to form One detection signal.

應注意的是,實作上,該感測器模組120被安排用來週期地收集即時CPU使用量數值、計算即時網路資料封包流量使用量的數值、收集用於指示即時輸入/輸出型樣類型的數值或位元以及收集即時風扇轉速、即時儲存區使用量數值、即時每秒讀寫次數、即時延遲以及即時檔案系統操作時間,舉例來說,該處理器115被安排用來執行感測器模組120的軟體部分以收集一或多個數值以得到一偵測訊號,而不同的時間間隔的不同資料數值係形成一偵測訊號,亦即一原始偵測訊號/結果,該感測器模組120所產生的該些偵測訊號會被依序地傳送至該處理器115。It should be noted that, in practice, the sensor module 120 is arranged to periodically collect real-time CPU usage values, calculate real-time network data packet traffic usage values, and collect real-time input/output type Such types of values or bits and collection of real-time fan speed, real-time storage area usage value, real-time read/write times per second, real-time delay, and real-time file system operation time. For example, the processor 115 is arranged to perform sense The software part of the detector module 120 collects one or more values to obtain a detection signal, and different data values at different time intervals form a detection signal, that is, an original detection signal/result. The detection signals generated by the detector module 120 are sequentially transmitted to the processor 115.

處理器115係用來接收該第一偵測訊號以根據一時間尺度來控制該顯示面板1101來於該顯示面板1101上顯示該第一偵測訊號的一資料型樣、當該操作者使用該計算機輸入裝置1102來於該顯示面板1101上標示出一區域以選取該資料型樣的一部分的型樣時使用相應於該資料型樣的該部分的型樣之該第一偵測訊號的一第一部分來產生一參考訊號、在該參考訊號產生之後接收從該感測器模組120所發送的該第二偵測訊號以及比較該參考訊號的特性與該第二偵測訊號的特性來進行一行為分析操作,該特性舉例來說包含有訊號振幅值、訊號頻率、頻率分布以及峰值幅度值(但不限定)的至少其中一個,此外,偵測訊號的其他不同的特性亦可應用於行為分析的操作中。The processor 115 is used to receive the first detection signal to control the display panel 1101 according to a time scale to display a data pattern of the first detection signal on the display panel 1101. When the operator uses the When the computer input device 1102 marks an area on the display panel 1101 to select a pattern of a part of the data pattern, a first detection signal corresponding to the pattern of the part of the data pattern is used. Part of it is to generate a reference signal, receive the second detection signal sent from the sensor module 120 after the reference signal is generated, and compare the characteristics of the reference signal with the characteristics of the second detection signal to perform a Behavior analysis operation, the characteristics include, for example, at least one of signal amplitude, signal frequency, frequency distribution, and peak amplitude (but not limited). In addition, other different characteristics of the detected signal can also be applied to behavior analysis In operation.

如果該部分的型樣被該操作者選取作為一異常型樣,則該處理器115用來通過使用相應於該異常型樣之該第一偵測訊號的該第一部分來產生一異常參考訊號,以及當該異常參考訊號的特性匹配(符合)於該第二偵測訊號的至少一部分的特性時判定發生了異常行為。而如果該部分的型樣被該操作者選取作為一正常型樣,則該處理器115用來通過使用相應於該正常型樣之該第一偵測訊號的該第一部分來產生一正常參考訊號,以及當該正常參考訊號的特性不匹配(不符合)於該第二偵測訊號的一部分的特性時判定發生了異常行為。該處理器115被安排用來基於一前先的感測結果(亦即該第一偵測訊號)來對一接下來進來的感測結果(例如該第二偵測訊號)來進行異常行為分析及/或行為預估。If the pattern of the part is selected by the operator as an abnormal pattern, the processor 115 is used to generate an abnormal reference signal by using the first part of the first detection signal corresponding to the abnormal pattern, And when the characteristic of the abnormal reference signal matches (conforms to) at least a part of the characteristic of the second detection signal, it is determined that an abnormal behavior has occurred. And if the pattern of the part is selected by the operator as a normal pattern, the processor 115 is used to generate a normal reference signal by using the first part of the first detection signal corresponding to the normal pattern , And when the characteristics of the normal reference signal do not match (do not match) the characteristics of a part of the second detection signal, it is determined that an abnormal behavior has occurred. The processor 115 is arranged to perform abnormal behavior analysis on a subsequent incoming sensing result (such as the second detection signal) based on a previous sensing result (that is, the first detection signal) And/or behavioral estimates.

第3圖是本發明一實施例基於一時間尺度(例如小時,但不限定)而顯示於該使用者介面裝置110的該顯示面板1101上的一原始資料型樣的範例示意圖,該時間尺度可以是以幾秒、幾分鐘、幾小時、幾天、幾週及/或幾個月為單位,而該處理器115可以使用或改變不同的時間尺度來控制該使用者介面裝置110的該顯示面板1101以顯示相同的偵測訊號的多個不同的資料型樣給該操作者,而該操作者可以直接看到該所顯示的資料型樣,並接著使用電腦滑鼠或電腦鍵盤,來標示或選取該顯示面板1101上的一個區域,以選取該原始資料型樣的一部分的型樣作為一參考型樣(該參考型樣可以是正常型樣或是異常型樣),對於該操作者來說,不需要手動鍵入某些固定數值作為臨界值來定義一正常型樣或異常型樣。Figure 3 is a schematic diagram of an example of a raw data pattern displayed on the display panel 1101 of the user interface device 110 based on a time scale (such as hours, but not limited) according to an embodiment of the present invention. The time scale can be In units of seconds, minutes, hours, days, weeks, and/or months, the processor 115 can use or change different time scales to control the display panel of the user interface device 110 1101 presents multiple different data patterns showing the same detection signal to the operator, and the operator can directly see the displayed data pattern, and then use the computer mouse or computer keyboard to mark or Select an area on the display panel 1101 to select a part of the original data pattern as a reference pattern (the reference pattern can be a normal pattern or an abnormal pattern), for the operator , There is no need to manually enter certain fixed values as critical values to define a normal pattern or an abnormal pattern.

第4圖是本發明另一實施例基於一時間尺度(例如小時,但不限定)而顯示於該使用者介面裝置110的該顯示面板1101上的一原始資料型樣的另一範例示意圖,如第4圖所示的例子,一操作者會使用電腦滑鼠或電腦鍵盤來標示或選取一區域(以虛線來表示)以選取該區域內之一部分所顯示的型樣作為一正常參考型樣。Figure 4 is a schematic diagram of another example of a raw data pattern displayed on the display panel 1101 of the user interface device 110 based on a time scale (such as hours, but not limited) according to another embodiment of the present invention, such as In the example shown in Figure 4, an operator uses a computer mouse or a computer keyboard to mark or select an area (indicated by a dotted line) to select a pattern displayed in a part of the area as a normal reference pattern.

第5圖是本發明另一實施例基於一時間尺度(例如小時,但不限定)而顯示於該使用者介面裝置110的該顯示面板1101上的一原始資料型樣的另一範例示意圖,如第5圖所示的例子,一操作者會使用電腦滑鼠或電腦鍵盤來標示或選取一區域(以虛線來表示)以選取該區域內之一部分所顯示的型樣作為一異常參考型樣。也就是說,該操作者可以通過使用該區域來標示出該原始資料型樣的一峰值部分,以選取該原始資料型樣的該峰值部分。Figure 5 is a schematic diagram of another example of a raw data pattern displayed on the display panel 1101 of the user interface device 110 based on a time scale (such as hours, but not limited) according to another embodiment of the present invention, such as In the example shown in Figure 5, an operator uses a computer mouse or a computer keyboard to mark or select an area (represented by a dotted line) to select a pattern displayed in a part of the area as an abnormal reference pattern. That is, the operator can mark a peak portion of the original data pattern by using the area to select the peak portion of the original data pattern.

在該操作者選取一部分的型樣作為一正常型樣或作為一異常型樣之後,該所選取的結果(亦即,該所選取的部分的型樣)被傳送至該處理器115,該處理器115係用來儲存該所選取的正常/異常型樣,並根據相應於該所選取的正常/異常型樣之該第一偵測訊號的一部分來產生一作為參考的正常/異常訊號,接著該處理器115用來比對該作為參考的正常/異常型樣的特性與該第二偵測訊號的特性來進行該行為分析操作。After the operator selects a part of the pattern as a normal pattern or as an abnormal pattern, the selected result (that is, the pattern of the selected part) is transmitted to the processor 115, and the processing The device 115 is used to store the selected normal/abnormal pattern, and generate a reference normal/abnormal signal according to a part of the first detection signal corresponding to the selected normal/abnormal pattern, and then The processor 115 is used to compare the characteristic of the normal/abnormal pattern as a reference with the characteristic of the second detection signal to perform the behavior analysis operation.

該所選取的部分的型樣係為一使用者所定義的正常型樣或一使用者所定義的異常型樣,以軟體方塊的實現來說,該處理器115會被用來啟動及執行一預測引擎以比對所接收進來的偵測訊號的特性與相應於該使用者所定義的正常/異常型樣之該參考訊號的特性來決定是否發生了一異常的行為,第6圖是該處理器115所執行的多個軟體程式方塊以即時進行行為分析的方塊示意圖,舉例來說,該處理器115所啟動並執行之該預測引擎605係被用來收集並得到從該感測器模組120所發送的多筆資料訊號。The pattern of the selected part is a normal pattern defined by the user or an abnormal pattern defined by the user. In terms of the realization of the software block, the processor 115 will be used to start and execute a The prediction engine compares the characteristics of the received detection signal with the characteristics of the reference signal corresponding to the normal/abnormal pattern defined by the user to determine whether an abnormal behavior has occurred. Figure 6 shows the process. A block diagram of a plurality of software program blocks executed by the processor 115 for real-time behavior analysis. For example, the prediction engine 605 activated and executed by the processor 115 is used to collect and obtain data from the sensor module 120 multiple data signals sent.

此外,一過濾模組610可以被該處理器115所使用來濾除掉該一或多個偵測訊號中的某些極值數值,以產生一或多個處理後的偵測訊號至該預測引擎605,接著該預測引擎605被安排用來比對一被處理後的偵測訊號的特性與相應於該使用者所定義的正常/異常型樣方塊615之該參考訊號的特性來產生一預測結果/訊號620、儲存該被處理後的偵測訊號至資料庫625以及產生該判斷結果(是否特性符合或不符合)至該行為分析模組630,該行為分析模組630係用來根據該判斷結果來決定是否發生了一異常行為,舉例來說,如果該處理後的偵測訊號的所有部分的特性均符合相應於該使用者所定義的正常型樣之該正常參考訊號的特性,則該行為分析模組630將會判斷出沒有發生任何的異常行為,而如果該處理後的偵測訊號的一部分的特性符合相應於該使用者所定義的異常型樣之該異常參考訊號的特性,則該行為分析模組630將判斷發生了一異常行為。In addition, a filtering module 610 can be used by the processor 115 to filter out certain extreme values in the one or more detection signals to generate one or more processed detection signals to the prediction Engine 605, and then the prediction engine 605 is arranged to compare the characteristics of a processed detection signal with the characteristics of the reference signal corresponding to the normal/abnormal pattern block 615 defined by the user to generate a prediction Result/signal 620, store the processed detection signal to the database 625, and generate the judgment result (whether the characteristic is consistent or not) to the behavior analysis module 630, and the behavior analysis module 630 is used according to the The judgment result is used to determine whether an abnormal behavior has occurred. For example, if the characteristics of all parts of the processed detection signal conform to the characteristics of the normal reference signal corresponding to the normal pattern defined by the user, then The behavior analysis module 630 will determine that no abnormal behavior has occurred, and if the characteristics of a part of the detected signal after the processing match the characteristics of the abnormal reference signal corresponding to the abnormal pattern defined by the user, Then the behavior analysis module 630 will determine that an abnormal behavior has occurred.

該預測結果620接著經由使用者所定義的規則方塊635而被回送至預測引擎605,該處理器115所執行的該使用者所定義的規則方塊635被安排用來根據該操作者的一要求來選取一相應的規則,舉例來說,該操作者欲調整使用者介面裝置110的該顯示面板1101上所顯示的時間尺度,該使用者所定義的規則方塊635會被安排基於該操作者的要求來調整所顯示的時間尺度,而在所顯示的該時間尺度基於該使用者所定義的規則方塊635而調整之後,該預測引擎605被安排用來根據該時間尺度來產生該預測結果620與該使用者所定義的正常/異常型樣,其中時間尺度的調整僅用來解釋上述操作的運作,並非是本發明的限制,此外,該所選取的策略可由該操作者所決定,並且可以是一較不積極的策略或是一比較積極的策略。The prediction result 620 is then sent back to the prediction engine 605 via a user-defined rule block 635. The user-defined rule block 635 executed by the processor 115 is arranged to be used according to a request of the operator. Select a corresponding rule. For example, if the operator wants to adjust the time scale displayed on the display panel 1101 of the user interface device 110, the user-defined rule block 635 will be arranged based on the operator's request To adjust the displayed time scale, and after the displayed time scale is adjusted based on the rule block 635 defined by the user, the prediction engine 605 is arranged to generate the prediction result 620 and the The normal/abnormal pattern defined by the user, in which the adjustment of the time scale is only used to explain the operation of the above operation, and is not a limitation of the present invention. In addition, the selected strategy can be determined by the operator and can be a A less aggressive strategy or a more aggressive strategy.

再者,在其他實施例,該偵測訊號可被該處理器115轉換至頻率域以產生具有頻率分布的一統計資料型樣/訊號並接著被顯示於使用者介面裝置110的該顯示面板1101上,使得該操作者可以選取該統計資料型樣的一頻率部分作為一正常型樣或作為一異常型樣,此設計變型亦可落入本發明範疇。Furthermore, in other embodiments, the detection signal can be converted into the frequency domain by the processor 115 to generate a statistical data pattern/signal with frequency distribution and then displayed on the display panel 1101 of the user interface device 110 The above allows the operator to select a frequency part of the statistical data pattern as a normal pattern or as an abnormal pattern. This design variant can also fall into the scope of the present invention.

此外,該操作者可以操控該使用者介面裝置110來選擇不同的時間尺度,使得相同的測訊號可以利用不同的時間尺度而顯示成不同的資料型樣。In addition, the operator can manipulate the user interface device 110 to select different time scales, so that the same measurement signal can be displayed in different data patterns using different time scales.

實作上,當該操作者改變該時間尺度時,該處理器115根據該原始偵測訊號來產生要被顯示於該顯示面板上的資料型樣,不同的時間尺度可以包含幾秒、幾分鐘、幾小時、幾天、幾週及/垂幾個月為單位,實作上,當接收到該第一偵測訊號時,該處理器115例如用來改變該時間尺度為一不同的時間尺度、根據該不同的時間尺度來控制該使用者介面裝置110的該顯示面板1101於該顯示面板1101上顯示該第一偵測訊號的一不同的資料型樣、當該操作者使用該使用者介面裝置110來標示出該顯示面板上的另一區域以選取該不同的資料型樣的該部分的型樣時使用相應於該不同的資料型樣的一部分的型樣之該第一偵測訊號的一第二部分來產生另一個參考訊號、在產生該另一個參考訊號之後接收從該感測器模組120所發送的該第二偵測訊號以及比對該另一個參考訊號的特性與該第二偵測訊號的特性來進行該行為分析操作。In practice, when the operator changes the time scale, the processor 115 generates a data pattern to be displayed on the display panel according to the original detection signal. Different time scales can include several seconds and minutes. , A few hours, a few days, a few weeks, and/or a few months. In practice, when the first detection signal is received, the processor 115 is used, for example, to change the time scale to a different time scale , Controlling the display panel 1101 of the user interface device 110 to display a different data pattern of the first detection signal on the display panel 1101 according to the different time scales, when the operator uses the user interface When the device 110 marks another area on the display panel to select the pattern of the part of the different data pattern, use the first detection signal corresponding to the pattern of the part of the different data pattern A second part generates another reference signal, receives the second detection signal sent from the sensor module 120 after generating the other reference signal, and compares the characteristics of the other reference signal with the first 2. Detect the characteristics of the signal to perform the behavior analysis operation.

在某些情況,即使以該時間尺度(例如秒)所顯示的該資料型樣的該部分的型樣係不同於以該另一個不同時間尺度(例如小時)所顯示的該另一個資料型樣的該部分的型樣,然而,該第一偵測訊號的該第一部分也可以是相當於該一偵測訊號的該第二部分。 以上所述僅為本發明之較佳實施例,凡依本發明申請專利範圍所做之均等變化與修飾,皆應屬本發明之涵蓋範圍。In some cases, even if the part of the data pattern displayed on the time scale (for example, seconds) is different from the other data pattern displayed on the other different time scale (for example, hours) However, the first part of the first detection signal can also be equivalent to the second part of the one detection signal. The foregoing descriptions are only preferred embodiments of the present invention, and all equivalent changes and modifications made in accordance with the scope of the patent application of the present invention shall fall within the scope of the present invention.

100:去中心化儲存系統 105:計算機儲存節點 110:使用者介面裝置 115:處理器 120:感測器模組 125:網路介面控制器 130:靜態隨機存取記憶體 135:主機介面控制器 140:動態隨機存取記憶體緩衝器 145:快閃記憶體控制器 150:硬碟驅動機 155:固態硬碟 605:預測引擎 610:過濾模組 620:預測結果方塊 625:資料庫 630:行為分析模組 635:使用者所定義的規則方塊 615:使用者所定義的型樣方塊 1101:顯示面板 1102:輸入裝置100: Decentralized storage system 105: computer storage node 110: User interface device 115: processor 120: sensor module 125: network interface controller 130: static random access memory 135: Host Interface Controller 140: dynamic random access memory buffer 145: Flash memory controller 150: Hard Disk Drive 155: Solid State Drive 605: prediction engine 610: filter module 620: prediction result block 625: database 630: Behavior Analysis Module 635: User-defined rule block 615: User-defined pattern box 1101: display panel 1102: input device

第1圖是本發明一實施例一去中心儲存系統的方塊示意圖。 第2圖是本發明一實施例一計算機儲存節點的方塊示意圖。 第3圖是本發明一實施例基於時間尺度例如秒來將一原始資料型樣顯示於該使用者介面裝置的該顯示面板上的範例示意圖。 第4圖是本發明另一實施例基於時間尺度例如小時來將一原始資料型樣顯示於該使用者介面裝置的該顯示面板上的範例示意圖。 第5圖是本發明另一其他實施例基於時間尺度例如小時來將一原始資料型樣顯示於該使用者介面裝置的該顯示面板上的範例示意圖。 第6圖是該處理器所執行的多個軟體程式區塊即時進行行為分析與預測進一步行為的實施例示意圖。Figure 1 is a block diagram of a decentralized storage system according to an embodiment of the present invention. Figure 2 is a block diagram of a computer storage node according to an embodiment of the present invention. FIG. 3 is a schematic diagram showing an example of displaying a raw data pattern on the display panel of the user interface device based on a time scale such as seconds according to an embodiment of the present invention. FIG. 4 is a schematic diagram showing an example of displaying a raw data pattern on the display panel of the user interface device based on a time scale such as hour according to another embodiment of the present invention. FIG. 5 is a schematic diagram showing an example of displaying a raw data pattern on the display panel of the user interface device based on a time scale such as hour according to another embodiment of the present invention. Figure 6 is a schematic diagram of an embodiment in which multiple software program blocks executed by the processor perform real-time behavior analysis and predict further behavior.

100:去中心化儲存系統 100: Decentralized storage system

105:計算機儲存節點 105: computer storage node

Claims (14)

一種使用於一分散式共用儲存系統中多個計算機儲存節點的其中之一的方法,包含有: 提供被一操作者所操作的一使用者介面裝置; 提供一感測器模組以感測該計算機儲存節點的至少一操作參數以產生一第一偵測訊號與跟隨該第一偵測訊號的一第二偵測訊號;以及 提供並使用一處理器來執行: 接收該第一偵測訊號以控制該使用者介面裝置的一顯示面板以於該顯示面板上根據一時間尺度來顯示該第一偵測訊號的一資料型樣; 當該操作者使用該使用者介面裝置來標示該顯示面板上的一區域以選取該資料型樣的一部分的型樣時,使用相應於該資料型樣的該部分的型樣之該第一偵測訊號的一第一部分來產生一參考訊號; 在產生該參考訊號之後,接收從該感測器模組所傳送的該第二偵測訊號;以及 比較該參考訊號的特性與該第二偵測訊號的特性以執行一行為分析操作。A method used in one of multiple computer storage nodes in a distributed shared storage system, including: Provide a user interface device operated by an operator; Providing a sensor module to sense at least one operating parameter of the computer storage node to generate a first detection signal and a second detection signal following the first detection signal; and Provide and use a processor to execute: Receiving the first detection signal to control a display panel of the user interface device to display a data pattern of the first detection signal on the display panel according to a time scale; When the operator uses the user interface device to mark an area on the display panel to select a pattern of a part of the data pattern, the first detection corresponding to the pattern of the part of the data pattern is used. Test a first part of the signal to generate a reference signal; After generating the reference signal, receiving the second detection signal transmitted from the sensor module; and The characteristic of the reference signal is compared with the characteristic of the second detection signal to perform a behavior analysis operation. 如申請專利範圍第1項所述之方法,其中該部分的型樣被該操作者選為一異常型樣,以及產生該參考訊號的步驟包括有: 通過使用相應於該異常型樣之該第一偵測訊號的該第一部分來產生一異常參考訊號;以及 比較該參考訊號的特性與該第二偵測訊號的特性的步驟包括有: 當該異常參考訊號的該特性符合該第二偵測訊號的至少一部分的特性時,判斷發生了一異常行為。For the method described in item 1 of the scope of patent application, the pattern of the part is selected by the operator as an abnormal pattern, and the steps of generating the reference signal include: Generating an abnormal reference signal by using the first part of the first detection signal corresponding to the abnormal pattern; and The steps of comparing the characteristics of the reference signal with the characteristics of the second detection signal include: When the characteristic of the abnormal reference signal matches at least a part of the characteristic of the second detection signal, it is determined that an abnormal behavior has occurred. 如申請專利範圍第1項所述之方法,其中該部分的型樣被該操作者選取為一正常型樣,以及產生該參考訊號的步驟包括有: 通過使用相應於該正常型樣之該第一偵測訊號的該第一部分來產生一正常參考訊號;以及 比較該參考訊號的特性與該第二偵測訊號的特性的步驟包括有: 當該正常參考訊號的該特性不符合該第二偵測訊號的一部分的特性時,判斷發生了一異常行為。For the method described in item 1 of the scope of patent application, the pattern of the part is selected by the operator as a normal pattern, and the steps of generating the reference signal include: Generating a normal reference signal by using the first part of the first detection signal corresponding to the normal pattern; and The steps of comparing the characteristics of the reference signal with the characteristics of the second detection signal include: When the characteristic of the normal reference signal does not match the characteristic of a part of the second detection signal, it is determined that an abnormal behavior has occurred. 如申請專利範圍第1項所述之方法,其中該至少一操作參數包含有CPU使用量、儲存區使用量、網路資料流量/封包使用量、輸入/輸出型樣類型、CPU溫度、風扇轉速、每秒讀寫次數(input/output operations per second,IOPS)、輸入/輸出延遲、及檔案系統操作時間。The method described in item 1 of the scope of patent application, wherein the at least one operating parameter includes CPU usage, storage area usage, network data flow/packet usage, input/output pattern type, CPU temperature, fan speed , Input/output operations per second (IOPS), input/output delay, and file system operation time. 如申請專利範圍第1項所述之方法,其中該參考訊號的該特性包含有一訊號振幅值、一訊號頻率、一頻率分布以及一峰值振幅值的至少其中之一。According to the method described in claim 1, wherein the characteristic of the reference signal includes at least one of a signal amplitude value, a signal frequency, a frequency distribution, and a peak amplitude value. 如申請專利範圍第1項所述之方法,另包含有: 改變該時間尺度為一不同時間尺度; 使用該處理器來控制該使用者介面裝置的該顯示面板以根 該不同時間尺度於該顯示面板上顯示該第一偵測訊號的一不同資料型樣; 當該操作者使用該使用者介面裝置來於該顯示面板上標示一另一區域以選取該不同資料型樣的該部分的型樣時,使用相應於該不同資料型樣的一部分的型樣之該第一偵測訊號的一第二部分來產生另一參考訊號; 在產生該另一參考訊號之後,接收從該感測器模組所傳送的該第二偵測訊號;以及 比較該另一參考訊號的特性與該第二偵測訊號的特性來執行該行為分析操作。For example, the method described in item 1 of the scope of patent application also includes: Change the time scale to a different time scale; Using the processor to control the display panel of the user interface device to display a different data pattern of the first detection signal on the display panel based on the different time scale; When the operator uses the user interface device to mark another area on the display panel to select the pattern of the part of the different data pattern, use the pattern corresponding to the part of the different data pattern A second part of the first detection signal to generate another reference signal; After generating the other reference signal, receiving the second detection signal transmitted from the sensor module; and The behavior analysis operation is performed by comparing the characteristics of the another reference signal with the characteristics of the second detection signal. 如申請專利範圍第6項所述之方法,其中該第一偵測訊號的該第一部分係相同於該第一偵測訊號的該第二部分,而以該時間尺度所顯示的該資料型樣的該部分的型樣係不同於以該不同時間尺度所顯示的該另一資料型樣的該部分的型樣。The method described in item 6 of the scope of patent application, wherein the first part of the first detection signal is the same as the second part of the first detection signal, and the data pattern displayed on the time scale The pattern of the part of is different from the pattern of the part of the other data pattern displayed on the different time scale. 一種於一分散式共用儲存系統中多個計算機儲存節點中的計算機儲存節點,包含有: 一使用者介面裝置,包含有: 一顯示面板,用來顯示資訊給一使用者;以及 至少一計算機輸入裝置,由一操作者所操作; 一感測器模組,用來感測該計算機儲存節點的至少一操作參數以產生一第一偵測訊號與跟隨該第一偵測訊號的一第二偵測訊號;以及 一處理器,耦接至該使用者介面裝置與該感測器模組,用來: 接收該第一偵測訊號以控制該使用者介面裝置的一顯示面板以於該顯示面板上根據一時間尺度來顯示該第一偵測訊號的一資料型樣; 當該操作者使用該使用者介面裝置來標示該顯示面板上的一區域以選取該資料型樣的一部分的型樣時,使用相應於該資料型樣的該部分的型樣之該第一偵測訊號的一第一部分來產生一參考訊號; 在產生該參考訊號之後,接收從該感測器模組所傳送的該第二偵測訊號;以及 比較該參考訊號的特性與該第二偵測訊號的特性以執行一行為分析操作。A computer storage node among multiple computer storage nodes in a distributed shared storage system, including: A user interface device, including: A display panel for displaying information to a user; and At least one computer input device operated by an operator; A sensor module for sensing at least one operating parameter of the computer storage node to generate a first detection signal and a second detection signal following the first detection signal; and A processor, coupled to the user interface device and the sensor module, for: Receiving the first detection signal to control a display panel of the user interface device to display a data pattern of the first detection signal on the display panel according to a time scale; When the operator uses the user interface device to mark an area on the display panel to select a pattern of a part of the data pattern, the first detection corresponding to the pattern of the part of the data pattern is used. Test a first part of the signal to generate a reference signal; After generating the reference signal, receiving the second detection signal transmitted from the sensor module; and The characteristic of the reference signal is compared with the characteristic of the second detection signal to perform a behavior analysis operation. 如申請專利範圍第8項所述之計算機儲存節點,其中該部分的型樣被該操作者選為一異常型樣,以及該處理器用來: 通過使用相應於該異常型樣之該第一偵測訊號的該第一部分來產生一異常參考訊號;以及 當該異常參考訊號的該特性符合該第二偵測訊號的至少一部分的特性時,判斷發生了一異常行為。For the computer storage node described in item 8 of the scope of patent application, the pattern of the part is selected as an abnormal pattern by the operator, and the processor is used to: Generating an abnormal reference signal by using the first part of the first detection signal corresponding to the abnormal pattern; and When the characteristic of the abnormal reference signal matches at least a part of the characteristic of the second detection signal, it is determined that an abnormal behavior has occurred. 如申請專利範圍第8項所述之計算機儲存節點,其中該部分的型樣被該操作者選取為一正常型樣,以及該處理器用來: 通過使用相應於該正常型樣之該第一偵測訊號的該第一部分來產生一正常參考訊號;以及 當該正常參考訊號的該特性不符合該第二偵測訊號的一部分的特性時,判斷發生了一異常行為。For the computer storage node described in item 8 of the scope of patent application, the pattern of the part is selected by the operator as a normal pattern, and the processor is used to: Generating a normal reference signal by using the first part of the first detection signal corresponding to the normal pattern; and When the characteristic of the normal reference signal does not match the characteristic of a part of the second detection signal, it is determined that an abnormal behavior has occurred. 如申請專利範圍第8項所述之計算機儲存節點,其中該至少一操作參數包含有CPU使用量、儲存區使用量、網路資料流量/封包使用量、輸入/輸出型樣類型、CPU溫度、風扇轉速、每秒讀寫次數(input/output operations per second,IOPS)、輸入/輸出延遲、及檔案系統操作時間。For example, the computer storage node described in item 8 of the scope of patent application, wherein the at least one operating parameter includes CPU usage, storage area usage, network data flow/packet usage, input/output pattern type, CPU temperature, Fan speed, input/output operations per second (IOPS), input/output delay, and file system operation time. 如申請專利範圍第8項所述之計算機儲存節點,其中該參考訊號的該特性包含有一訊號振幅值、一訊號頻率、一頻率分布以及一峰值振幅值的至少其中之一。For the computer storage node described in claim 8, wherein the characteristic of the reference signal includes at least one of a signal amplitude value, a signal frequency, a frequency distribution, and a peak amplitude value. 如申請專利範圍第8項所述之計算機儲存節點,其中該處理器用來: 改變該時間尺度為一不同時間尺度; 使用該處理器來控制該使用者介面裝置的該顯示面板以根 該不同時間尺度於該顯示面板上顯示該第一偵測訊號的一不同資料型樣; 當該操作者使用該使用者介面裝置來於該顯示面板上標示一另一區域以選取該不同資料型樣的該部分的型樣時,使用相應於該不同資料型樣的一部分的型樣之該第一偵測訊號的一第二部分來產生另一參考訊號; 在產生該另一參考訊號之後,接收從該感測器模組所傳送的該第二偵測訊號;以及 比較該另一參考訊號的特性與該第二偵測訊號的特性來執行該行為分析操作。The computer storage node described in item 8 of the scope of patent application, wherein the processor is used to: Change the time scale to a different time scale; Using the processor to control the display panel of the user interface device to display a different data pattern of the first detection signal on the display panel based on the different time scale; When the operator uses the user interface device to mark another area on the display panel to select the pattern of the part of the different data pattern, use the pattern corresponding to the part of the different data pattern A second part of the first detection signal to generate another reference signal; After generating the other reference signal, receiving the second detection signal transmitted from the sensor module; and The behavior analysis operation is performed by comparing the characteristics of the another reference signal with the characteristics of the second detection signal. 如申請專利範圍第13項所述之計算機儲存節點,其中該第一偵測訊號的該第一部分係相同於該第一偵測訊號的該第二部分,而以該時間尺度所顯示的該資料型樣的該部分的型樣係不同於以該不同時間尺度所顯示的該另一資料型樣的該部分的型樣。Such as the computer storage node described in claim 13, wherein the first part of the first detection signal is the same as the second part of the first detection signal, and the data displayed in the time scale The pattern of the part of the pattern is different from the pattern of the part of the other data pattern displayed on the different time scale.
TW109108697A 2019-05-10 2020-03-17 Method and computer storage node of shared storage system for abnormal behavior detection/analysis TWI747199B (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US16/408,477 2019-05-10
US16/408,477 US11042459B2 (en) 2019-05-10 2019-05-10 Method and computer storage node of shared storage system for abnormal behavior detection/analysis

Publications (2)

Publication Number Publication Date
TW202042063A true TW202042063A (en) 2020-11-16
TWI747199B TWI747199B (en) 2021-11-21

Family

ID=73046220

Family Applications (2)

Application Number Title Priority Date Filing Date
TW109108697A TWI747199B (en) 2019-05-10 2020-03-17 Method and computer storage node of shared storage system for abnormal behavior detection/analysis
TW110139003A TW202205093A (en) 2019-05-10 2020-03-17 Method and computer storage node of shared storage system for abnormal behavior detection/analysis

Family Applications After (1)

Application Number Title Priority Date Filing Date
TW110139003A TW202205093A (en) 2019-05-10 2020-03-17 Method and computer storage node of shared storage system for abnormal behavior detection/analysis

Country Status (3)

Country Link
US (2) US11042459B2 (en)
CN (1) CN111913656B (en)
TW (2) TWI747199B (en)

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115238933B (en) * 2022-09-23 2022-12-09 西安德纳检验检测有限公司 Wind turbine generator inertia response detection method, device and system based on multipoint measurement
CN116049908B (en) * 2023-04-03 2023-06-06 北京数力聚科技有限公司 Multi-party privacy calculation method and system based on blockchain
CN116599867B (en) * 2023-07-18 2023-11-24 中国人民解放军国防科技大学 Internet of things sensor abnormality detection method and system based on dynamic diagram

Family Cites Families (15)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7194445B2 (en) 2002-09-20 2007-03-20 Lenovo (Singapore) Pte. Ltd. Adaptive problem determination and recovery in a computer system
EP1673744B1 (en) * 2003-09-05 2010-01-27 Sensitech Inc. Automatic conditioning of data accumulated by sensors monitoring supply chain processes
WO2008121945A2 (en) * 2007-03-30 2008-10-09 Netqos, Inc. Statistical method and system for network anomaly detection
TWI331868B (en) 2007-06-11 2010-10-11 Univ Nat Pingtung Sci & Tech Detecting method of network invasion
CN102859517B (en) * 2010-05-14 2016-07-06 株式会社日立制作所 Time series data managing device, system and method
TWI533159B (en) 2013-10-18 2016-05-11 國立臺灣科技大學 A continuous identity authentication method for computer users
TWI548235B (en) 2014-01-14 2016-09-01 Chunghwa Telecom Co Ltd Network anomaly traffic monitoring system with normal distribution mode
WO2016054605A2 (en) * 2014-10-02 2016-04-07 Reylabs Inc. Systems and methods involving diagnostic monitoring, aggregation, classification, analysis and visual insights
TWM509371U (en) 2015-04-13 2015-09-21 Acer Inc Monitoring apparatus and computer apparatus
US10789119B2 (en) * 2016-08-04 2020-09-29 Servicenow, Inc. Determining root-cause of failures based on machine-generated textual data
US10565513B2 (en) 2016-09-19 2020-02-18 Applied Materials, Inc. Time-series fault detection, fault classification, and transition analysis using a K-nearest-neighbor and logistic regression approach
TWI591489B (en) 2016-12-14 2017-07-11 Chunghwa Telecom Co Ltd Intelligent monitoring and warning device and method for distributed software defined storage system
DE102017104884B4 (en) * 2017-03-08 2019-02-14 Mts Consulting & Engineering Gmbh System and method for determining error images from sensor data in product validation and manufacturing processes
US10756983B2 (en) * 2017-12-08 2020-08-25 Apstra, Inc. Intent-based analytics
US10902654B2 (en) * 2018-04-20 2021-01-26 Palantir Technologies Inc. Object time series system

Also Published As

Publication number Publication date
TW202205093A (en) 2022-02-01
TWI747199B (en) 2021-11-21
US20210271580A1 (en) 2021-09-02
US11042459B2 (en) 2021-06-22
US11507484B2 (en) 2022-11-22
CN111913656A (en) 2020-11-10
US20200356454A1 (en) 2020-11-12
CN111913656B (en) 2024-04-19

Similar Documents

Publication Publication Date Title
TWI747199B (en) Method and computer storage node of shared storage system for abnormal behavior detection/analysis
US8024613B2 (en) Method and system for managing apparatus performance
US9418020B2 (en) System and method for efficient cache utility curve construction and cache allocation
US9298633B1 (en) Adaptive prefecth for predicted write requests
US9122607B1 (en) Hotspot detection and caching for storage devices
US7146467B2 (en) Method of adaptive read cache pre-fetching to increase host read throughput
US20060259686A1 (en) Storage control method, program, and apparatus
US20130174176A1 (en) Workload management in a data storage system
US20180121237A1 (en) Life cycle management of virtualized storage performance
KR102478392B1 (en) System and method for identifying ssds with lowest tail latencies
CN103502925B (en) A kind of monitoring record management method and device
US7962692B2 (en) Method and system for managing performance data
US8775786B1 (en) Boot caching for boot acceleration within data storage systems
WO2019120226A1 (en) Data access prediction method and apparatus
US9594781B2 (en) Estimation of query input/output (I/O) cost in database
US20230305930A1 (en) Methods and systems for affinity aware container preteching
JPH0247746A (en) Control of memory
US10949359B2 (en) Optimizing cache performance with probabilistic model
US9652155B2 (en) Computer system, cash data management method, and computer
JP2021144629A (en) Data management system and data management method
JP2004264970A (en) Program, information processor, and method for outputting log data in information processor
JP2016012288A (en) Test device, test program, and test method
US7756648B1 (en) Method and apparatus for facilitating in-situ vibration testing of disk drives
JP7436567B2 (en) Storage system and unauthorized access detection method
JP7424052B2 (en) Control program, control method and control device